CVE-2011-1179
published 2011-04-18CVE-2011-1179: The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows remote attackers to cause a denial of service (crash) and possibly…
PriorityP426medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
3.89%
89.1th percentile
The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to (1) plugin/nsScriptablePeer.cpp and (2) plugin/plugin.cpp, which trigger multiple uses of an uninitialized pointer.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | spice-xpi | — | — |
| redhat | spice-xpi | — | — |
| redhat | spice-xpi | — | — |
CVSS provenance
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r42g-6jh5-6q2v: The SPICE Firefox plug-in (spice-xpi) 2
ghsa_unreviewed·2022-05-17
CVE-2011-1179 [MEDIUM] CWE-119 GHSA-r42g-6jh5-6q2v: The SPICE Firefox plug-in (spice-xpi) 2
The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to (1) plugin/nsScriptablePeer.cpp and (2) plugin/plugin.cpp, which trigger multiple uses of an uninitialized pointer.
Red Hat
spice-xpi: unitialized pointer writes possible when getting plugin properties
vendor_redhat·2011-04-07·CVSS 5.1
CVE-2011-1179 [MEDIUM] spice-xpi: unitialized pointer writes possible when getting plugin properties
spice-xpi: unitialized pointer writes possible when getting plugin properties
The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to (1) plugin/nsScriptablePeer.cpp and (2) plugin/plugin.cpp, which trigger multiple uses of an uninitialized pointer.
Package: spice-xpi (Red Hat Enterprise Linux 5) - Affected
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/44060http://www.redhat.com/support/errata/RHSA-2011-0426.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0427.htmlhttp://www.securityfocus.com/bid/47269http://www.securitytracker.com/id?1025304http://www.vupen.com/english/advisories/2011/0899https://bugzilla.redhat.com/attachment.cgi?id=487006&action=diffhttps://bugzilla.redhat.com/show_bug.cgi?id=689931https://exchange.xforce.ibmcloud.com/vulnerabilities/66777http://secunia.com/advisories/44060http://www.redhat.com/support/errata/RHSA-2011-0426.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0427.htmlhttp://www.securityfocus.com/bid/47269http://www.securitytracker.com/id?1025304http://www.vupen.com/english/advisories/2011/0899https://bugzilla.redhat.com/attachment.cgi?id=487006&action=diffhttps://bugzilla.redhat.com/show_bug.cgi?id=689931https://exchange.xforce.ibmcloud.com/vulnerabilities/66777
2011-04-18
Published